Privacy statement
This privacy statement explains which personal data we process through pagewren.com and the PageWren client portal (portal.pagewren.com), why we process it, and which rights you have. We handle your data with care and comply with the General Data Protection Regulation (GDPR).
1. Who is responsible for your data?
PageWren is a service of Picazzo Research & Development, which is the controller for the personal data processed through this website and the client portal.
- Legal name: Picazzo Research & Development
- Trade name: PicazzoLabs (PageWren is a PicazzoLabs service)
- Address: Zinkstraat 24, Box C4687, 4823 AD Breda, the Netherlands
- Dutch Chamber of Commerce (KvK) number: 42060545
- VAT identification number: NL005464235B85
- Email: [email protected] (legal and privacy matters: [email protected])
We have no telephone contact channel; all contact runs by email.
2. Which personal data do we process?
The public website at pagewren.com is an informational site. It sets no cookies, uses no tracking pixels and no advertising networks. It does keep simple visitor statistics, which store nothing at all on your device; these are described below. We process only the data described here.
- Website request (intake form) — the "Request your page" button takes you to our intake form at portal.pagewren.com/start. That form is served by our own client portal and what you submit there is stored on our own server in the Netherlands — it is not a
mailto:link and it does not go through a third-party form service. We process: your business name, contact name, email address, telephone number, town, country (chosen from a list), type of business, your description of the business, your services or products, any design wishes, the web address of an existing website, any further comments, and up to eight images you upload (together with your confirmation that you hold the rights to use them). Business name, email address, town and that rights confirmation are required; every other field is optional. We use this to prepare a preview website and a quote for you, and to contact you about it — see the first two bullets of section 3 for the legal bases. We keep an intake for 12 months (section 6). You can also simply email us instead of using the form. - Referral link opens — our partners share links of the form
/start?ref=…. When such a link is opened we record only the partner's own code and the moment it was opened, so a partner can see that their link is being used. No IP address, and nothing that identifies you, is stored with it. - Client portal account — if you are a PageWren client, we process your email address and the one-time login codes we send you, plus a session token, so you can sign in to the portal securely. There are no passwords.
- Uploads and change requests — files you upload in the portal (images and PDF documents) and the change requests you submit, so we can carry out the work on your website.
- Billing — your name, business details and subscription status. Payments run through Stripe; card and payment details are handled by Stripe only — we never see or store your card data (see section 4).
- Technical server logs — when you visit the website or portal, our hosting infrastructure (Cloudflare and our own servers in the Netherlands) automatically records your IP address, user-agent (browser and device type) and the referring page in short-lived server logs. This happens only for the ordinary technical handling of your request and for security and abuse prevention (for example DDoS mitigation), based on our legitimate interest (art. 6(1)(f) GDPR). These logs are kept for approximately 24–72 hours and then deleted automatically; we do not use them for profiling, marketing or to identify you personally.
- Visitor statistics — we count visits using Umami, analytics software we run on our own server in the Netherlands. It is not a third-party service and no visitor data leaves our own infrastructure. It places nothing on your device: no cookies, no local storage, no device fingerprint. Per page view it records the page address and title, the website you came from, and your country, browser, operating system, device type, screen size and language. Your IP address is not stored — the statistics server uses it only for a moment, to work out which country you are in and to compute a hashed visitor number, and then discards it. This data is never shared with anyone, is never used for advertising and cannot be traced back to you personally. If your browser sends a "Do Not Track" signal, nothing is recorded at all.
Websites we host for our clients: for the visitor data of the client websites we build and host, the client business is the controller and we act only as a processor within the meaning of art. 28 GDPR, under a written data processing agreement. That processing is described in the privacy statement of the client website concerned, not in this document.
We do not build profiles of you, do not use your data for advertising and do not sell personal data. You are not legally required to provide us with personal data; without the requested details, however, we cannot handle your request or provide the service.
3. Why and on which legal basis do we process your data?
We process your data for the purposes above, on the following legal bases (art. 6 GDPR):
- to answer your question and offer our service, based on our legitimate interest (art. 6(1)(f) GDPR) in handling enquiries about our services;
- to enter into and perform the agreement with you (art. 6(1)(b) GDPR) — the portal login, uploads, change requests, hosting and billing;
- to comply with a legal obligation (art. 6(1)(c) GDPR), for example the Dutch fiscal duty to retain invoices;
- to keep the website and portal secure (the technical server logs), based on our legitimate interest (art. 6(1)(f) GDPR);
- to see how our website is found and used, so we can improve it (the visitor statistics), based on our legitimate interest (art. 6(1)(f) GDPR) in a website that works and can be found. Because these statistics store nothing on your device and hold no data that identifies you, we do not ask for consent for them; you can object at any time (section 7) and you can switch them off yourself as described in the cookie policy.
4. Who receives your data?
We do not share your data with advertisers and do not sell it. Your data may be processed by service providers who work on our behalf:
- Cloudflare — CDN, DNS and hosting infrastructure for the website and portal. Cloudflare processes traffic data (including IP addresses) solely on our behalf, under a data processing agreement.
- Self-hosted servers in the Netherlands — the intake form at portal.pagewren.com/start, the client portal, uploads, website previews and the visitor statistics all run on our own servers located in the EU (the Netherlands). The statistics software is ours and self-hosted, so it is not a recipient of your data in the sense of this section: nothing is passed to an analytics company.
- MXRoute — delivery of transactional email (such as login codes and service messages).
- Stripe — payment processing and the customer billing portal. Stripe processes your payment details as a processor for the payment itself, and additionally acts as an independent controller for its own purposes such as fraud prevention and compliance with financial regulations; see Stripe's own privacy statement for details.
- Hostinger — domain name registration, where applicable to your website's domain.
That is the whole list. The website's fonts are served from our own domain rather than from Google Fonts or another font service, so simply viewing a page sends your IP address to no one beyond the providers named above. Since August 2026 Google is no longer on this list for exactly that reason. See section 6 of the cookie policy.
5. Transfers outside the European Economic Area (EEA)
Where personal data is processed outside the EEA (for example by providers established in the United States, such as Cloudflare, Stripe or MXRoute), this takes place under appropriate safeguards: an adequacy decision (such as the EU–US Data Privacy Framework) or the standard contractual clauses adopted by the European Commission (SCCs, art. 46 GDPR). We maintain standard contractual clauses as a fallback option.
6. How long do we keep your data?
We do not keep your data longer than necessary:
- intake-form submissions, including any images uploaded with them: 12 months;
- referral-link open counts: for as long as the partner programme runs. These hold only a partner code and a timestamp, and nothing about the visitor;
- contact emails: up to 2 years after our last contact;
- portal account data, uploads and change requests: for the duration of your subscription; after cancellation your website and data are removed after the current billing period ends;
- data we are legally required to keep (such as invoices): the statutory period (7 years for Dutch tax purposes);
- technical server logs: approximately 24–72 hours;
- visitor statistics: kept while we operate the website, so we can compare one period with another. These records contain no IP address and no identifier that can be traced back to you.
7. Your rights
You have the right to:
- access your data (art. 15 GDPR);
- have your data corrected (art. 16 GDPR);
- have your data erased (art. 17 GDPR);
- have the processing restricted (art. 18 GDPR);
- object to the processing (art. 21 GDPR);
- have your data transferred (data portability, art. 20 GDPR).
Send your request to [email protected]. We respond within the statutory period of one month.
8. Right to object to direct marketing
We do not use your data for direct marketing. Should that change, you have the right to object to it at any time, free of charge.
9. Automated decision-making
We do not make decisions about you based solely on automated processing (profiling) that produce legal effects for you or similarly significantly affect you (art. 22 GDPR).
10. Minors
This website is not directed at persons under 16. We do not knowingly collect data from minors without the consent of a parent or guardian. If you believe we have nevertheless processed a minor's data, please contact us at [email protected] and we will delete it.
11. Security
We take appropriate technical and organisational measures to protect your data (art. 32 GDPR), including encrypted traffic (HTTPS), HttpOnly session cookies, one-time login codes instead of passwords, access restriction, and hosting on maintained infrastructure within the EU.
12. Complaints
Do you have a complaint about how we handle your personal data? Please contact us at [email protected]. You also have the right to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
13. Changes
We may update this privacy statement when our website, portal or the way we process data changes. The date at the top shows the latest revision.
